Apple iOS Flaw Could Give Attacker Access via iMessage

Google Project Zero researchers found an iOS vulnerability that could let an attacker snoop on a victim’s phone remotely.

Apple’s most recent update to iOS wasn’t simply to add features: It also patched a significant vulnerability discovered by Google Project Zero. Google security researchers Samuel Groß and Natalie Silvanovich found the vulnerability, designated CVE-2019-8646, which could allow a threat actor to gain access to iOS devices and read their contents using a malicious iMessage as an attack vector.

A malicious actor also could exploit the flaw to remotely read one-time-passwords sent via SMS — a technique frequently used as part of a two-factor authentication scheme.

Google followed responsible disclosure and notified Apple in May. Apple patched the vulnerability within the 90-day window that Google allowed. Silvanovich will present details of the vulnerability in a Black Hat USA briefing, Apple iMessage Flaw Lets Remote Attackers Read Files on iPhones.

iOS users who subscribe to automatic updates should already have applied the patch; other iOS users are encouraged to update to iOS 12.4 immediately.

For more, read here.

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

 

 

Dark Reading’s Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

More Insights

Read More HERE

Leave a Reply